Expired accounts: ‘Please help, I can no longer log in — what now?’
Wednesday, April 13, 2011 at 8:59AM System administrators and helpdesk agents will be familiar with the problem; temporary hires or external employees are assigned a user account with an expiration date. Meanwhile, their contract is renewed without the IT department being notified, so in the morning you find the users at your desk complaining about being unable to work.
Solution 1: A link with the HRM system
A structural solution is to link your Active Directory to the HRM system (e.g. PeopleSoft, SAP HCM, Lawson). A ‘connector’ will automatically detect contracts that are about to expire and determine exactly when an account must be blocked. Any modifications in the HRM system will also be automatically implemented by the connector in Active Directory enabling employees to continue working as usual. This connector can also operate on the basis of a phased approach. For instance, you can configure a ‘grace period’ that will allow users to log in until 2 days after their contract has expired. After this grace period, the user account will be quarantined for a period 90 days, after which it will be completely erased, including the data and mailbox.
Solution 2: Self-service based on e-forms
If temporary hires or external employees are not registered in the HRM system, this can be solved by having the relevant manager handle requests for user accounts. A ‘web shop’ with electronic forms (e-forms) is made available, so that the manager can request user accounts for these employees. This can be configured so that requests are carried out immediately or must first be approved by the IT department. The web shop features will also allow managers to perform management tasks for the user accounts that they have requested, such as resetting passwords and unlocking, blocking, releasing or renewing accounts. This means temporary employees will no longer have to call in the help of IT if their contract is renewed. Everything can be handled directly by their manager.
Solution 3: Automatic reporting and notifications
It is now possible to combine solution 3 with the solutions discussed above. UMRA by Tools4Ever makes it possible to convert the expiration date in Active Directory into a legible date with consummate ease. With solution 2, managers still run the risk of forgetting to renew contracts for temporary hires or external employees. To prevent this, it is possible to monitor accounts that are about to expire in, say, 2 weeks, on a daily basis. Notifications will automatically be sent to the account itself and to the person who requested the account. This means the organisation is always kept up-to-date with regard to the accounts that threaten to expire. This can prevent a lot of frustration.
Want to learn more about how UMRA can streamline your identity management process, visit our website: www.tools4ever.com

